CVE-2026-91206: Apache Roller: Reflected XSS in the optional LDAP comment authenticator
Apache Roller 6.1.5 has a moderate reflected XSS in its optional LDAP comment authenticator.
Apache disclosed CVE-2026-91206, a reflected cross-site scripting flaw in Apache Roller 6.1.5. The optional LDAP comment authenticator writes request parameter values into its HTML form without proper neutralization. Apache rates it moderate, with CVSS 3.1 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Exploitation requires a victim to interact with a crafted link; no in-the-wild use is described.
- Affects Apache Roller 6.1.5 only.
- Optional LDAP comment authenticator reflects request parameters into HTML.
- CVSS 3.1 base score is 6.1 (medium); user interaction required.
- No exploitation in the wild is reported.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91206 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5 Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without...
This source does not provide full text. Read it at seclists.org.